This Privacy Policy explains how Compaxis Pty Ltd (ABN 75 698 385 456), an Australian company ("Compaxis", "we", "us", "our"), collects, uses, discloses, and protects your personal information when you use compaxis.ai, the Compaxis Hub desktop application, and the Compaxis SQ4 GGUF model files (together, the "Services").
We handle personal information in accordance with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). Where applicable, we also comply with the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
1. Information we collect
1.1 Account and licence information. Compaxis uses a licence-key model — there are no usernames, passwords, or multi-factor authentication. When you buy a plan we collect:
- Your email address — to deliver your licence key and send essential service communications.
- Your name, if you provide it at checkout.
- A device identifier generated by the Hub — used only to enforce the number of seats on your licence.
1.2 Payment information. Payments are processed by Paddle.com Market Limited as Merchant of Record. We do not store your card number, expiry, or CVC. We store your Paddle customer ID (to link your account to Paddle) and transaction records (plan purchased, amount, timestamp). Paddle's handling of payment data is governed by Paddle's own privacy policy.
1.3 Hub telemetry (off by default). Telemetry is opt-in — it is switched off by default and you can enable it during setup or in settings. If you enable it, the Hub sends:
- Application version and operating system
- GPU model (for compatibility and support)
- Which models you downloaded and basic feature usage counts
- Anonymous crash reports
What we never collect: the content of your prompts, the model's responses, or your local files. These never leave your device.
1.4 Data stored only on your device (not collected by Compaxis). The following stays local and is never transmitted to us:
- Downloaded SQ4 GGUF model files
- Any chat or test history you create in the Hub
- Your Hub settings and preferences
- Your licence token
1.5 Website data. The marketing site uses strictly necessary cookies only (see clause 8). If we add analytics, we use a privacy-respecting provider that does not track you across sites, and we name it here.
1.6 Bug reports. If you submit a bug report, we collect your description of the issue and any logs or screenshots you choose to attach. Bug reports are forwarded to our task-tracking provider for resolution.
2. How we use your information
- Deliver and activate your licence
- Process payments and subscriptions
- Send essential service and security communications
- Enforce licence seat limits and plan entitlements
- Diagnose crashes and improve the product (aggregated, where telemetry is enabled)
- Prevent fraud, abuse, and Terms violations
- Comply with legal obligations
We do not: sell your personal information; use your data for advertising or ad targeting; train AI models on your data, prompts, or outputs; or share your data with third parties for their marketing.
3. Local-first by design
The Compaxis Hub runs entirely on your machine, and the SQ4 model files are static GGUF binaries. They do not phone home, do not stream your prompts anywhere, and do not require an internet connection to run inference. Inference happens locally; your prompts and the model's outputs are never seen, logged, or stored by Compaxis.
The Hub contacts our servers only to: activate your licence, check for updates, download paid models you are entitled to, and submit anonymous crash reports if you have enabled telemetry.
4. How we share your information
We share data with the following providers, strictly as necessary to operate the Services:
- Paddle — payment processing and subscription management
- Keygen — licence key issuance and seat enforcement
- Crash-reporting provider — anonymous crash reports, only if you enable telemetry
- Infrastructure providers (hosting, CDN) — website delivery and model file downloads
- Task-tracking provider — bug report content you submit
We do not sell personal information to anyone.
5. Data retention
- Account information — while your account is active, plus 30 days after a deletion request
- Payment and transaction records — 7 years (Australian tax law)
- Usage telemetry — 90 days (rolling)
- Bug reports — 1 year
- Licence and device data — while the licence is active, plus 30 days
After the retention period, data is permanently deleted or anonymised.
6. Data security
- Transport security: HTTPS/TLS for all network communication
- Encryption at rest for sensitive data such as licence tokens
- Rate limiting on API routes
- Access control for administrative functions
- Audit logging of administrative actions
No system is 100% secure. While we take reasonable steps to protect your data, we cannot guarantee absolute security.
Breach notification. In the event of a data breach affecting your personal information, we will notify you without undue delay. For EU/EEA users we notify within 72 hours where required by the GDPR; for users covered by the Australian Notifiable Data Breaches scheme we notify within the timeframes required by the OAIC; for all other users we notify within 30 days of becoming aware. Notification will describe the nature of the breach, the data affected, the likely consequences, and the steps we are taking.
7. Your rights
7.1 All users. Regardless of location, you may: access your personal data, correct inaccurate data, delete your account and associated data, export your data in a portable format, and object to processing based on legitimate interest. To exercise these rights, email .
7.2 Australian users (Privacy Act 1988). Under the APPs you may access your personal information (APP 12) and request correction (APP 13). If you believe we have breached the APPs you may complain to us, and if unsatisfied you may escalate to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
7.3 EU/EEA users (GDPR). You additionally have the right to erasure, data portability, restriction of processing, objection to processing based on legitimate interest, and to lodge a complaint with your local supervisory authority. Legal bases: contract performance (account, payment, licence activation), legitimate interest (security, fraud prevention, product improvement), and consent (optional telemetry). Your data is processed in Australia; where we transfer data outside the EU/EEA we rely on Standard Contractual Clauses or other appropriate safeguards.
7.4 California users (CCPA). You have the right to know what we collect and how it is used, to request deletion, to opt out of the "sale" of personal information (we do not sell), and to non-discrimination for exercising your rights. Categories collected: identifiers and commercial information. Categories sold: none.
8. Cookies and local storage
- Strictly necessary cookies — essential session cookies on the website; not used for tracking.
- Functional storage — your browser's local storage for non-sensitive preferences (such as theme). No personal data or tracking identifiers.
- Infrastructure cookies — may be set by our hosting/CDN for load balancing or bot protection; strictly functional.
- No tracking or advertising — we do not use advertising cookies, tracking pixels, third-party analytics cookies, or cross-site tracking of any kind.
9. Children's privacy
The Services are not directed at individuals under the age of 16. We do not knowingly collect personal information from anyone under 16. If you believe a child under 16 has provided us with personal information, contact us and we will delete it promptly.
10. International data transfers
Compaxis is based in Australia and your data is primarily processed and stored in Australia. Some providers may process data in other jurisdictions — Paddle (payment data), and our infrastructure providers (which may cache content at globally distributed edge nodes). Where data is transferred internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses where required by the GDPR.
11. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide at least 30 days' notice via email to your registered address or through a prominent notice on the Services. The "Last updated" date above indicates when this policy was last revised. Your continued use of the Services after the effective date constitutes acceptance of the changes.
12. Contact us
Privacy enquiries and general support:
Compaxis Pty Ltd (ABN 75 698 385 456)
Registered office: 1/23 Oxford Road, Ingleburn NSW 2565, Australia
We aim to respond to privacy enquiries within 30 days.
13. Regulatory contacts
- Office of the Australian Information Commissioner (OAIC) — oaic.gov.au — complaints under Australian law
- EU Data Protection Authorities — your local supervisory authority — complaints under the GDPR
- California Attorney General — oag.ca.gov — complaints under the CCPA